San Francisco Chronicle

Owner of Hacker’s List is IDd; he says criticism is misplaced

-

He calls himself an ethical hacker who helps companies and individual­s fight back against the bad guys operating online. Over the years, Charles Tendell also has emerged as a commentato­r in the news media about the threat posed by overseas hackers and is a former co-host of an online radio show about security.

But behind the scenes, Tendell, a Colorado resident and a decorated Iraq War veteran, started a new website called Hacker’s List that allows people to anonymousl­y post bids to hire a hacker. Many users have sought to find someone to steal an e-mail password, break into a Facebook account or change a school grade.

‘Off-the-cuff idea’

Tendell, 32, who owns a consulting firm in Denver called Azorian Cyber Security, confirmed last week that he was the sole owner of the website. He said Hacker’s List, which began as something of an “off-the-cuff idea,” grew far faster than he anticipate­d.

“I never expected it to turn into what it is,” said Tendell, a graduate of the University of Phoenix who became certified as an informatio­n systems security profession­al and an ethical hacker in 2011. “I was testing the waters and wanted to see if it works.”

The verdict is still out on whether Hacker’s List, which started in November, will work as a business. The propensity is for people to use it as a way to search for hackers willing to break the law as opposed to doing legitimate online investiga- tions and surveillan­ce.

The website has caused a stir in the online world because of its unusual approach to matching ordinary people looking to do a bit of private espionage with so-called hackers-for-hire. The company, which collects a fee for every completed assignment, has garnered considerab­le news coverage, including a front-page article in the New York Times in January, with much of the coverage focusing on the dubious legality of the requests.

Until now, the identity of the founder had remained a mystery. An employee of Hacker’s List named “Jack” had said on a number of occasions that the owner was not ready to talk.

The lack of disclosure surroundin­g Hacker’s List is one reason the hackers-for-hire service has drawn considerab­le scorn from security consultant­s, who say the website is an invitation to illegal and unethical behavior. Some lawyers have said the owners could be civilly liable for maintainin­g a service that permits customers to seek to hire hackers for illegal activities.

Others have wondered whether the website is an elaborate online joke or a sting operation set up by federal authoritie­s.

The website’s rules of operation repeatedly note that the service does not condone illegal activity, but that appears to have done little to stop people from seeking to hire hackers to carry out tasks that most would say break the law.

But Tendell said much of the criticism of Hacker’s List was misplaced. He noted that even if an illegal job were posted by an anonymous user, it would not necessaril­y be carried out. He said clearly illegal job postings were removed if someone complained, but he said what mattered were the jobs that were completed.

“No one is going to complete an illegal project through my website,” he said.

Still, Hacker’s List has had its share of operationa­l hiccups, and its website has crashed a number of times. More than 4,000 potential jobs have been posted, but many have not received a bid from a hacker. Tendell said about 250 jobs had been completed.

Some banned

Some hackers have tried to disrupt the service, and more recently it has banned hackers who were looking to defraud job posters.

Last week, Twitter suspended the Hacker’s List account, which automatica­lly sends out new job postings. Twitter would not comment on the suspension, but many of the account’s tweets promoted jobs like “hack a PayPal account.” A Twitter spokesman would not comment on the reason for the suspension. Tendell said he did not know why Twitter suspended the account.

Tendell’s role in setting up Hacker’s List was unmasked in part by Erik Solomonson, a blogger who lives in New York and works for a Web hosting company. He decided to do a bit of digging into the formation of Hacker’s List. Solomonson unearthed an archived domain registrati­on statement for Hacker’s List from October, just before the website went live, that listed Tendell as the administra­tor and contact person for the site.

A few weeks later, Tendell’s name was removed from a revised domain registrati­on. The name that replaced his was David Harper, who is said to live in New Zea- land and could not be contacted.

The older domain registrati­on for Hacker’s List also suggested there might be a tie-in with Neighborho­od Hacker, another online hackers-for-hire firm in Colorado. Tendell said he had done work with Neighborho­od Hacker but was not an owner of that company.

Solomonson said Tendell’s involvemen­t with Hacker’s List pointed to how difficult it was for consumers to assess the legitimacy of firms that say they offer legal hackers-for-hire services.

It’s inappropri­ate for someone like Tendell, who calls himself a “white hat hacker,” to be involved in any way with an operation that potentiall­y is profiting from illegal activity, Solomonson said.

Newspapers in English

Newspapers from United States